Skip to main content

Apple Calendar

MCP server for Apple Calendar on macOS.

Provides access to calendars and events through EventKit. Keep Calendar as the system of record while enabling agents to read, create, update, and delete events.

When to use

  • Calendar-only workflows
  • EventKit-backed calendar access without the all-in-one server
  • Tighter app-level separation for scheduling

What It Does

  • Discover and list calendars
  • Create, read, update, and delete events
  • Tool discovery helpers search_tools and get_tool_info for context-constrained clients
  • Today resources and planning prompts
  • Health checks that distinguish empty results from blocked access
  • Read fallback through Calendar.app automation when native EventKit reads are blocked on supported local setups
  • Permission recovery: calendar_permission_guide, calendar_recheck_permissions

Install On This Mac

Quick start (uvx, from PyPI)

With uv installed:

uvx apple-calendar-mcp

No clone, no venv management.

From a clone
git clone https://github.com/JonathanRReed/Apple-MCPs.git
cd Apple-MCPs
uv sync --all-packages

This builds one workspace environment with every server's entry point in .venv/bin (for example .venv/bin/apple-calendar-mcp). You can also point an MCP client at Apple-Calendar-MCP/start.sh, which prefers uv run and falls back to a plain venv bootstrap (Python 3.11+ required).

Install In AI Agents

Generic MCP client config
{
  "mcpServers": {
    "apple-calendar": {
      "command": "uvx",
      "args": ["apple-calendar-mcp"],
      "env": {
        "APPLE_CALENDAR_MCP_SAFETY_MODE": "safe_manage"
      }
    }
  }
}

Running from a clone instead? Use /path/to/Apple-MCPs/Apple-Calendar-MCP/start.sh as the command with empty args.

Claude Code example
claude mcp add --transport stdio --scope project apple-calendar -- uvx apple-calendar-mcp

Safety Modes

  • safe_readonly
  • safe_manage
  • full_access

Calendar allowlists

Set these environment variables in your MCP client's configuration, then restart the server:

Variable Effect
APPLE_CALENDAR_MCP_ALLOWED_CALENDARS Comma-separated calendar names the server may read or modify. Calendar listings, event listings, event details, and Calendar resources respect this scope.
APPLE_CALENDAR_MCP_WRITE_ALLOWED_CALENDARS Additional comma-separated calendar names the server may create, update, or delete events in. It does not hide other readable calendars.

For an assistant that may read your schedule but only write to a dedicated calendar:

{
  "APPLE_CALENDAR_MCP_SAFETY_MODE": "safe_manage",
  "APPLE_CALENDAR_MCP_WRITE_ALLOWED_CALENDARS": "AI Planning"
}

Leaving either allowlist unset or empty applies no restriction from that list. When both are set, writes must pass both; safe_readonly blocks all writes regardless of either list. Moving an event checks both the source and destination calendar. A write with an unresolved target is rejected when an allowlist is configured.

Names are exact, case-sensitive matches after trimming configuration whitespace. Every calendar with a matching name is included, so use unique calendar names for security-sensitive scopes. calendar_health reports the configured write allowlist.

These are policies enforced by the Python MCP server, not a macOS sandbox. Direct use of the native helper or bridge library does not enforce them. macOS permissions still apply, and your MCP client may send returned data to its model provider.

Transport

stdio is the default and recommended transport. Set APPLE_CALENDAR_MCP_TRANSPORT=streamable-http (with optional APPLE_CALENDAR_MCP_HOST and APPLE_CALENDAR_MCP_PORT) to serve Streamable HTTP instead.

macOS Permissions

  • Calendar access is required
  • calendar_health reports access_status, read access, and write access so agents can detect blocked permissions before treating an empty window as real data

Launch Checklist

  • Add uvx apple-calendar-mcp (or a clone's Apple-Calendar-MCP/start.sh) to your MCP client
  • Reload or reconnect the client so the Calendar tool surface is loaded into context
  • Call calendar_health first
  • If access is blocked or access_status is not_determined, call calendar_permission_guide
  • After changing macOS permissions, call calendar_recheck_permissions

Prompting Notes

  • tools/list returns the full Calendar tool surface. Context-constrained clients can use search_tools first, then get_tool_info for the Calendar tool they need.
  • Before creating events, confirm the date, time, duration, and title with the user
  • Use Calendar for scheduled time blocks, meetings, and appointments

Release files for apple-calendar-mcp 1.0.5

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for apple-calendar-mcp 1.0.5
File Size Uploaded
apple_calendar_mcp-1.0.5.tar.gz 36.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for apple-calendar-mcp 1.0.5
File Interpreter ABI Platform
apple_calendar_mcp-1.0.5-py3-none-any.whl Python 3 none any Details

Total release size: 64.4 kB

Release files / apple_calendar_mcp-1.0.5.tar.gz

Download URL apple_calendar_mcp-1.0.5.tar.gz
Size 36.4 kB
Tags Source
SHA-256 checksum
How to use checksums
a040579e9366a2986a0ce88efe01f33156bb69f5b900fdb230ca7d796fe62185
BLAKE2b-256 checksum
How to use checksums
af32e80aac558cb3abda7ac9429adaa1046c0a3ee651397b18724c267d3c9901
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 25, 2026.

Transparency log

Release files / apple_calendar_mcp-1.0.5-py3-none-any.whl

Download URL apple_calendar_mcp-1.0.5-py3-none-any.whl
Size 28.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
b43290cf4b485a5447adf3471cbe9cb01a4193b47a6a47da22e83c453f1e1a38
BLAKE2b-256 checksum
How to use checksums
8017a9318979d40622892247ccb23daf5e668b08e6695cf7f38128810213f811
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 25, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

1.0.5 This release

2 release files

1.0.4

2 release files

1.0.3

2 release files

1.0.2

2 release files

1.0.1

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page